diff --git a/.githooks/pre-commit b/.githooks/pre-commit index 0415670..8a70271 100755 --- a/.githooks/pre-commit +++ b/.githooks/pre-commit @@ -13,7 +13,7 @@ NC='\033[0m' # No Colour FAILED=0 -# ---------- Frontend (prettier —write, then eslint) ---------- +# ---------- Frontend (prettier --write, then eslint) ---------- FRONTEND_STAGED=$(git diff --cached --name-only -- 'frontend/' | head -1) if [ -n "$FRONTEND_STAGED" ]; then printf "${YELLOW}Auto-formatting staged frontend files with prettier...${NC}\n" @@ -31,15 +31,51 @@ if ! cd frontend && npx eslint . 2>&1; then fi cd .. -# ---------- Backend (go vet) ---------- +# ---------- Backend checks (only if backend/ files changed) ---------- BACKEND_FILES=$(git diff --cached --name-only -- 'backend/' | head -1) if [ -n "$BACKEND_FILES" ]; then printf "${YELLOW}Checking go vet...${NC}\n" - if ! cd backend && go vet ./... 2>&1; then + if ! cd backend && go vet -tags "test,dev" ./... 2>&1; then printf "${RED}✖ go vet failed${NC}\n" FAILED=1 fi cd .. + + printf "${YELLOW}Checking staticcheck...${NC}\n" + if ! cd backend && staticcheck -tags "test,dev" ./... 2>&1; then + printf "${RED}✖ staticcheck failed${NC}\n" + FAILED=1 + fi + cd .. + + printf "${YELLOW}Checking gosec...${NC}\n" + if ! cd backend && gosec -severity medium -tags "test,dev" ./... 2>&1; then + printf "${RED}✖ gosec failed${NC}\n" + FAILED=1 + fi + cd .. + + printf "${YELLOW}Checking go mod tidy...${NC}\n" + cp backend/go.sum backend/go.sum.bak + cp backend/go.mod backend/go.mod.bak + cd backend && go mod tidy && cd .. + if ! diff -q backend/go.sum backend/go.sum.bak >/dev/null 2>&1 || ! diff -q backend/go.mod backend/go.mod.bak >/dev/null 2>&1; then + printf "${RED}✖ go.mod or go.sum out of date — run 'go mod tidy' and stage the changes${NC}\n" + FAILED=1 + fi + rm -f backend/go.sum.bak backend/go.mod.bak +fi + +# ---------- Global checks ---------- + +printf "${YELLOW}Checking secrets...${NC}\n" +if command -v gitleaks >/dev/null 2>&1; then + if ! gitleaks detect --source . --no-banner 2>&1; then + printf "${RED}✖ gitleaks detected secrets${NC}\n" + FAILED=1 + fi +else + printf " (gitleaks not installed — skipping; CI will catch secrets)\n" fi # ---------- Result ----------